In cybersecurity, a proof of concept (PoC) is code or a demonstration showing that a vulnerability can actually be exploited, usually without a fully weaponised payload.
How PoCs are used
When researchers find a vulnerability, a PoC proves it is real: it may crash a service, read a file, open the calculator app or show that code runs with higher privileges. Vendors use PoCs to reproduce and fix bugs, bug bounty programs often require them, and defenders use public PoCs to test whether their systems are vulnerable and to write detection rules.
A PoC is not the same as a weaponised exploit: it typically lacks reliability across versions, evasion and a real malicious payload. But the gap between the two is often small.
Why PoCs matter
Publication of a PoC is a turning point for risk. Once working code is on GitHub or social media, mass scanning and exploitation frequently begin within hours or days – as seen with Log4Shell in 2021 and with many VPN and file-transfer flaws since. Security teams therefore watch for “PoC released” as a signal to patch urgently, and vulnerability prioritisation systems such as CISA KEV and EPSS take it into account. If attackers already use a flaw before a fix exists, it is a zero-day.
PoCs are also a lure: researchers have found thousands of fake PoC repositories on GitHub that contain malware aimed at the security professionals who download them.
Best practices
- Track public PoCs for software you use and speed up patching when one appears.
- Run third-party PoC code only in isolated lab environments after reviewing it.
- Researchers should follow coordinated disclosure and give vendors time to release fixes before publishing PoCs.